<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: useful custom reports in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/227164#M65378</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the reply, after some thought your post made sense. I am still getting to know how the SORT BY and GROUPEDBY work in conjunction with eachother in generating reports. any explanantion in that direction will be helpful.&amp;nbsp; Is there any detailed documentation with examples where I can refer for further learning. Thank you&lt;/P&gt;</description>
    <pubDate>Wed, 15 Aug 2018 14:14:35 GMT</pubDate>
    <dc:creator>DAYANAND</dc:creator>
    <dc:date>2018-08-15T14:14:35Z</dc:date>
    <item>
      <title>useful custom reports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/178868#M55603</link>
      <description>&lt;P&gt;Hey all,&lt;/P&gt;&lt;P&gt;I want to create some custom reports to get more useful information about what is going on in my network.&lt;/P&gt;&lt;P&gt;I would like to know - just informational - which reports do you use in your daily business?&lt;/P&gt;&lt;P&gt;Respectively which reports you consider as useful.&lt;/P&gt;&lt;P&gt;Until now, I created one report that shows me the denied packets for every last week.&lt;/P&gt;&lt;P&gt;Can you give me some more hints?&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 06:44:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/178868#M55603</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-09-27T06:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: useful custom reports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/178954#M55610</link>
      <description>&lt;P&gt;Here are three&amp;nbsp; reports that I always schedule to run every day.&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Reset report: I have a report that looks for the 'reset-client', 'reset-both', and 'reset-server' actions going from untrust to my dmz zone. This includes anything that reset likely due to a vulnerability or threat being identified.&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Risk Report: This report includes the widgets Risky Users, Botnet, Spyware Infected Hosts, and Top Spyware Threats.&lt;/P&gt;&lt;P&gt;3) Summary Reports: Daily PDF Reports which includes the following widgets; Bandwidth trent, Top Denied Sources, Top Secuirty Rules, Risk Trent, Top Destination Countries, Top Source Countries, Threat Tred, Top Destination Zones, Top Source Zones, Top Connections, Top Destinations, Top Sources, Top Denied Applications, Top Egress Interfaces, Top Denied Destinations, Top Ingress Interfaces. So most of the widgets really.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 13:32:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/178954#M55610</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-09-27T13:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: useful custom reports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/180521#M55867</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your answer!&lt;/P&gt;&lt;P&gt;I have a question to your risk reports:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;are these custom reports or predefined?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't find Risky Users&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and my second question:&lt;/P&gt;&lt;P&gt;When I take a look into Spyware Infected Hosts, there are only external ip addresses. What do I need that information for?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and 3)&lt;/P&gt;&lt;P&gt;Where can I find Bandwidth trent, Risk Trent and Threat Tred?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2017 10:52:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/180521#M55867</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-10-06T10:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: useful custom reports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/180525#M55869</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/50331"&gt;@MPI-AE&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The reset report that I have listed at the top is the only custom report within that list. Risky Users can be found when you are building your Report Groups, it's one of the predefined reports available within that list.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You'd want to keep the Spyware infected hosts so that you can see if an internal address shows up; I would also verify where those external IPs were going and who was communicating with them. Depending on the actual threat detected and in what direction the PA sees it going, you may see an external IP when it's one of your internal users infected.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Bandwidth trend, Risk trend, and threat trend are again predefined reports. You can add these when you are building the Report Group or if you create PDF Summary reports.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2017 12:33:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/180525#M55869</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-10-06T12:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: useful custom reports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/185144#M56682</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hey BPry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I built a report group and added the predefined report risky-users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am wondering now, why that report doesn't show up under Monitor -&amp;gt; Reports?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 13:46:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/185144#M56682</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-11-02T13:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: useful custom reports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/185147#M56683</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/50331"&gt;@MPI-AE&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Can't really answer that one I'm afraid, I don't have any idea why it wouldn't show up there.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 13:56:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/185147#M56683</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-11-02T13:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: useful custom reports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/187149#M56993</link>
      <description>&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480" target="_blank"&gt;@BPry&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I built a good overall report, thanks for your hints.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Still a last question to the risky users:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;there are a lot of different risky users shown up in the report.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They have a risk of 4 or 5.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They are sorted by "Bytes"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why are they risky? What am I supposed to do? What entries are important?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm confused.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 10:12:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/187149#M56993</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-11-15T10:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: useful custom reports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/187183#M56999</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/50331"&gt;@MPI-AE&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It generally takes the risk associated with the app-ids identified on that user's traffic. So if you haven't modified the app-id's associated risk then it's likely just displaying your most active users.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 13:55:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/187183#M56999</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-11-15T13:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: useful custom reports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/187912#M57104</link>
      <description>&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480" target="_blank"&gt;@BPry&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have some more questions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-The Spyware Infected Hosts, how does the firewall know that hosts are spyware affected, especially external hosts? But also internal hosts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-URL Report:&lt;/P&gt;&lt;P&gt;Is it possible to create a custom url report that doesn't list the top blocked url's but the less blocked url's?&lt;/P&gt;&lt;P&gt;The problem is: I have a url report that lists the top 50 blocked url's. That report isn't really helpful because all url's shown there are web-advertisments, that are accessed over 1k times.&lt;/P&gt;&lt;P&gt;I would like to get url's that are accessed only a few times, maybe 1 or 2. Because most likely, that's an url that was accessed consciously by a user. So I can proactively unblock these url's. Do you know what I mean?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 10:03:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/187912#M57104</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-11-20T10:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: useful custom reports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/187953#M57115</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/50331"&gt;@MPI-AE&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Spyware Infected Hosts are generated by what the firewall sees through the Threat database. Specifically, if you run the following filter '( subtype eq spyware )' on the threat database you'll see what it's picking up on. In this case the 'Victim' is going to be what is considered a Infected Host.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for a URL report, your best bet there would be to simply ignore the whole web-advertisements category if it isn't something you are interested in seeing. For that I would likely recommend you create a custom report looking at the URL Log database, you would want to have the following in your Query Builder as to not display any of the web-advertisements category.&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;not ( category eq web-advertisements )&lt;/PRE&gt;</description>
      <pubDate>Mon, 20 Nov 2017 13:35:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/187953#M57115</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-11-20T13:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: useful custom reports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/188760#M57243</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yeah that's a good idea.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry, but another question comes into my mind:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my report group that is sent every Sunday, there are included: botnet, Spyware Infected Hosts, Top denied applications, Top egress interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is, these reports just show facts for the sunday.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a possibilty to change that from sunday to the whole last calendar week?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 08:24:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/188760#M57243</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-11-27T08:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: useful custom reports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/188822#M57253</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/50331"&gt;@MPI-AE&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Since those reports are actually built into the firewall there isn't a way to modify them that I know of. That being said, all of the reports can be generated as a custom report that specifies the last 7 days so you have a full week.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 14:31:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/188822#M57253</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-11-27T14:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: useful custom reports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/188864#M57259</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/50331"&gt;@MPI-AE&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480" target="_blank"&gt;@BPry&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I built a good overall report, thanks for your hints.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Still a last question to the risky users:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;there are a lot of different risky users shown up in the report.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They have a risk of 4 or 5.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They are sorted by "Bytes"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why are they risky? What am I supposed to do? What entries are important?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm confused.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IMO, the "risk" number is to be a guage not even so much a guide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hell, application "web-browsing" is a 4 and "FTP" is a 5.&amp;nbsp; I wouldn't necessarily base any report or security policy around a risk score.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 21:20:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/188864#M57259</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-11-27T21:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: useful custom reports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/188865#M57260</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Risky users can be extremely helpful if you've taken the time to customize the application risk level specific to the company you are working for. At default value you are very much correct, the risk level is likely not a good indicator to actually use for anything.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 21:24:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/188865#M57260</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-11-27T21:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: useful custom reports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/188867#M57261</link>
      <description>&lt;P&gt;Agreed, my meaning was around the stock value of apps.&amp;nbsp; Again IMO, it's akin to a shiny object you can show to leadership.&amp;nbsp; Doesn't really mean you're more secure at a "3" with no security profiles than someone at a "5" who's running Threat/URL/WF services.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 21:29:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/188867#M57261</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-11-27T21:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: useful custom reports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/188924#M57271</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, when I want to create a custom report with the spyware infected hosts:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pa.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12662iF207F8CAE94F66C4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pa.JPG" alt="pa.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I do this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There aren't so much options..&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 09:56:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/188924#M57271</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-11-28T09:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: useful custom reports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/188985#M57281</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/50331"&gt;@MPI-AE&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The spyware report is actually pulling from the Threat database, with the ( subtype eq spyware ) as the actor.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 18:20:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/188985#M57281</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-11-28T18:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: useful custom reports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/227159#M65374</link>
      <description>&lt;P&gt;Hi, we can create custom reports as per our requirement, you could define the filters which you wish to observes the logs for like desti, zone, etc..One could define a time frame as well&amp;nbsp; like daily, weekly and so on.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However I have a few questions that I still need ansewrs for :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.) There is an option for grouping the traffic log reports based on destination etc.... There is a maximum limit of 500 logs only that it can produce logs for. Does that mean I get only 500 logs from the time of capture ? If I am right what happens to the traffic generated after that ? Is there a way to incerase the limit &amp;gt;500. Because a custome report on Panorama with a limit of 500 means nothing even if I capture hourly.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 13:09:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/227159#M65374</guid>
      <dc:creator>DAYANAND</dc:creator>
      <dc:date>2018-08-15T13:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: useful custom reports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/227162#M65377</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/74832"&gt;@DAYANAND&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It's the top 500 logs depending on whatever your sort criteria be. So if I use bytes for example, it's the TOP 500 logs as determined by the amount of bytes logged. If you are combining a 'Sort By' and 'Group By' operating within the same request you'll be limited to the Top 500 logs; however if you remove the 'Group By' you have access to as much as the Top 10,000 logs.&lt;/P&gt;&lt;P&gt;You have to get creative in the way you generate the reports so that the report actually gives you what you are looking for. I've yet to want to run any report that I wasn't able to work around these limitations in some way or another.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know that there are multiple FRs to increase this capability if you want to reach out to your SE and add your vote to those requests.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 13:38:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/227162#M65377</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-08-15T13:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: useful custom reports</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/227164#M65378</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the reply, after some thought your post made sense. I am still getting to know how the SORT BY and GROUPEDBY work in conjunction with eachother in generating reports. any explanantion in that direction will be helpful.&amp;nbsp; Is there any detailed documentation with examples where I can refer for further learning. Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 14:14:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/useful-custom-reports/m-p/227164#M65378</guid>
      <dc:creator>DAYANAND</dc:creator>
      <dc:date>2018-08-15T14:14:35Z</dc:date>
    </item>
  </channel>
</rss>

